<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:22:48 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-40943</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-40943</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Siemens SIMATIC Drive Controller CPU 1504D TF, Siemens SIMATIC Drive Controller CPU 1507D TF, Siemens SIMATIC ET 200SP CPU 1510SP F-1 PN, Siemens SIMATIC ET 200SP CPU 1510SP-1 PN, Siemens SIMATIC ET 200SP CPU 1512SP F-1 PN, Siemens SIMATIC ET 200SP CPU 1512SP-1 PN, Siemens SIMATIC ET 200SP CPU 1514SP F-2 PN, Siemens SIMATIC ET 200SP CPU 1514SP-2 PN, Siemens SIMATIC ET 200SP CPU 1514SPT F-2 PN, Siemens SIMATIC ET 200SP CPU 1514SPT-2 PN and 93 more&lt;/p&gt;
&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Siemens SIMATIC Drive Controller CPU 1504D TF, Siemens SIMATIC Drive Controller CPU 1507D TF, Siemens SIMATIC ET 200SP CPU 1510SP F-1 PN, Siemens SIMATIC ET 200SP CPU 1510SP-1 PN, Siemens SIMATIC ET 200SP CPU 1512SP F-1 PN, Siemens SIMATIC ET 200SP CPU 1512SP-1 PN, Siemens SIMATIC ET 200SP CPU 1514SP F-2 PN, Siemens SIMATIC ET 200SP CPU 1514SP-2 PN, Siemens SIMATIC ET 200SP CPU 1514SPT F-2 PN, Siemens SIMATIC ET 200SP CPU 1514SPT-2 PN and 93 more&lt;/p&gt;
&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-40943</guid>
    </item>
  </channel>
</rss>
